Deception y HoneypotsDeception and Honeypots
Señuelos y credenciales trampa para detección temprana de intrusos.Decoys and trap credentials for early intruder detection.
¿Qué es este servicio?What is this service?
Es sembrar señuelos por la red: servidores falsos que parecen valiosos, archivos con nombres tentadores, credenciales trampa en la memoria de los equipos y usuarios ficticios en el directorio. Ningún empleado tiene motivo para tocarlos, así que cualquier interacción es un incidente.
Planting decoys across the network: fake servers that look valuable, files with tempting names, trap credentials in machine memory and fictitious users in the directory. No employee has any reason to touch them, so any interaction is an incident.
¿Para qué se usa?What is it used for?
Sirve por una razón concreta: la tasa de falsos positivos es prácticamente cero. Mientras el SIEM entrega mil alertas para encontrar una buena, un señuelo tocado significa que alguien está husmeando donde no debe. No previene nada ni reemplaza al EDR: detecta al que ya pasó los controles y está reconociendo la red. Es un complemento barato con una señal altísima.
It works for one specific reason: the false positive rate is practically zero. While the SIEM hands over a thousand alerts to find one good one, a touched decoy means somebody is poking where they should not. It prevents nothing and replaces no EDR: it catches whoever already got past the controls and is now mapping the network. A cheap complement with an extremely high signal.
Qué beneficios traeBenefits it delivers
- Genera alertas de altísima fidelidad, de las que se atienden sin discutir si son ruido.
- Detecta movimiento lateral y reconocimiento interno, que es la fase donde todavía se puede frenar un ransomware.
- Las credenciales trampa delatan al atacante en cuanto las usa, porque no abren nada real y disparan la alerta al intentarlo.
- Cuesta poco comparado con lo que aporta: no requiere licencias por equipo ni ampliar la ingesta del SIEM.
- Produces extremely high-fidelity alerts, the kind acted on without debating whether they are noise.
- Detects lateral movement and internal reconnaissance, the phase where ransomware can still be stopped.
- Trap credentials expose the attacker the moment they are used, because they open nothing real and fire the alert on the attempt.
- It costs little for what it gives: no per-endpoint licences and no extra SIEM ingestion.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No es obligatorio en Costa Rica y ningún regulador local lo menciona.
- Si el señuelo registra la actividad de personas identificables, ese registro es tratamiento de datos personales y entra bajo la Ley 8968, que sigue vigente: conviene revisarlo con el área legal antes de desplegar.
- It is not mandatory in Costa Rica and no local regulator mentions it.
- If the decoy records the activity of identifiable people, that record is personal data processing and falls under Law 8968, still in force: worth reviewing with legal before deploying.
InternacionalInternational
- Ningún marco lo exige por nombre.
- Se valora como evidencia de madurez en evaluaciones de terceros y en las revisiones de capacidad de detección.
- Hay un matiz laboral que conviene atender: usar señuelos para vigilar a empleados concretos, en vez de para detectar intrusos, cambia el análisis legal en la mayoría de jurisdicciones.
- No framework requires it by name.
- It is valued as evidence of maturity in third-party assessments and detection capability reviews.
- There is an employment law nuance worth attending to: using decoys to watch specific employees, rather than to detect intruders, changes the legal analysis in most jurisdictions.
Requisitos mínimosMinimum requirements
- Segmentos de red donde colocar los señuelos de forma que resulten creíbles y no queden aislados del camino del atacante.
- Documentar en el inventario que esos activos son señuelos, para que nadie los administre por error ni los meta en un escaneo.
- Integración con el SIEM o con el equipo de guardia, porque una alerta de señuelo no puede esperar al lunes.
- Un procedimiento distinto al triaje normal: si el señuelo suena, se asume compromiso y se investiga, no se descarta.
- Network segments where decoys can sit credibly, not isolated from the attacker path.
- Documenting in the inventory that those assets are decoys, so nobody administers them by mistake or includes them in a scan.
- Integration with the SIEM or the on-call team, because a decoy alert cannot wait until Monday.
- A procedure different from normal triage: if the decoy fires, assume compromise and investigate rather than dismiss.
Plazo típico de entregaTypical delivery time
El despliegue inicial va de tres a seis semanas: diseñar los señuelos para que resulten creíbles en el entorno concreto de la organización, colocarlos, sembrar las credenciales trampa e integrar las alertas. Después es mantenimiento ligero, pero sí hay que renovarlos: un señuelo que lleva dos años igual y sin actualizar deja de parecer un sistema vivo.
Initial deployment takes three to six weeks: designing decoys so they look credible in the specific environment, placing them, seeding trap credentials and integrating alerts. After that it is light maintenance, but they do need refreshing: a decoy unchanged for two years stops looking like a live system.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.